Home Cyber Security News Fortinet Confirms Active Exploitation of FortiCloud SSO Authentication Bypass Flaw

Fortinet Confirms Active Exploitation of FortiCloud SSO Authentication Bypass Flaw

0
Fortinet Confirms Active Exploitation of FortiCloud SSO Authentication Bypass Flaw

Fortinet has confirmed active exploitation of critical FortiCloud single sign-on (SSO) authentication bypass vulnerabilities affecting its enterprise security products.

The company disclosed that threat actors are exploiting these vulnerabilities to gain unauthorized administrative access to compromised devices, creating significant risk for organizations relying on Fortinet infrastructure.

Vulnerability Overview

In December 2025, Fortinet identified two FortiCloud SSO bypass vulnerabilities (CVE-2025-59718 and CVE-2025-59719) during an internal code audit.

These flaws allowed unauthenticated attackers to bypass SSO authentication through crafted SAML requests sent to FortiOS, FortiWeb, FortiProxy, and FortiSwitch Manager devices when FortiCloud SSO was enabled.

CVE IDCVSS ScoreAffected ProductsAttack VectorStatus
CVE-2025-597189.8 (Critical)FortiOS, FortiWeb, FortiProxy, FortiSwitch ManagerNetwork/SAML BypassActive Exploitation
CVE-2025-597199.8 (Critical)FortiOS, FortiWeb, FortiProxy, FortiSwitch ManagerNetwork/SAML BypassActive Exploitation

Fortinet recently identified that threat actors are actively exploiting these vulnerabilities in real-world attacks.

The company observed unexpected login activity on customer devices resembling previous SSO bypass attempts.

However, the discovery of successful exploits against fully patched systems indicates a new attack vector beyond the originally disclosed vulnerabilities.

Security teams should monitor for the following IOCs associated with active exploitation:

Compromised User Accounts:

  • cloud-noc@mail.io
  • cloud-init@mail.io

Source IP Addresses:

  • 104.28.244.115
  • 104.28.212.114
  • 37.1.209.19 (third-party observed)
  • 217.119.139.50 (third-party observed)

Malicious Admin Accounts Created:

  • audit
  • backup
  • itadmin
  • secadmin
  • support

Post-compromise, threat actors create local administrative accounts for persistence. Fortinet’s analysis reveals that attackers establish these accounts immediately after gaining SSO access, enabling continued access even if SSO credentials are disabled.

Organizations should audit all administrator accounts for unexpected entries created during suspicious timeframes.

Fortinet recommends immediate implementation of the following controls:

Restrict Administrative Access: Apply local-in policies to limit administrative interface access to trusted IP ranges only, preventing internet-exposed management ports.

Disable FortiCloud SSO: As a temporary workaround, disable the FortiCloud SSO feature via System Settings or CLI command set admin-forticloud-sso-login disable.

Monitor and Update: Organizations should regularly monitor the Fortinet PSIRT page for patch availability and register for security update notifications through the Fortinet Community.

If IOCs are discovered on compromised devices, Fortinet recommends treating the system as fully compromised and executing the following remediation steps:

  • Update to the latest firmware version (7.6 recommended)
  • Restore configuration from a known-clean backup
  • Rotate all administrative credentials and connected LDAP/AD accounts
  • Conduct a thorough audit of VPN configurations and user accounts

Fortinet is actively developing a permanent patch to address this new attack vector. An updated advisory will be released once the fix scope and deployment timeline are finalized.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here